PT-2014-3099 · Json-C+3 · Json-C+3

Florian Weimer

·

Publicado

2014-04-08

·

Atualizado

2024-06-15

·

CVE-2013-6371

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions json-c versions prior to 0.12
Description The issue allows context-dependent attackers to cause a denial of service, specifically CPU consumption, by providing crafted JSON data that involves collisions, thus exploiting the hash functionality.
Recommendations For versions prior to 0.12, update to version 0.12 or later to resolve the issue.

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-1691
ALT-PU-2019-4163
ALT-PU-2020-2322
ALT-PU-2023-6481
ALT-PU-2023-6841
CVE-2013-6371
MGASA-2014-0175
OPENSUSE-SU-2024:10013-1
OPENSUSE-SU-2024:10498-1
RHSA-2014:0703
RHSA-2014_0703
USN-2245-1

Produtos afetados

Alt Linux
Red Hat
Ubuntu
Json-C